Ransomware Crews Have Started Reading Your Org Chart
New research from Zscaler's ThreatLabz, reported by The Register, tracked 351 victims across 334 organisations in a single month-long ransomware campaign, and the crews weren't chasing the CEO. Nearly two-thirds of the people they went after held manager-level titles or above, the average target was 46, and three-quarters worked in accounting, finance, sales, operations, HR or marketing.
The reframe is worth sitting with. Security teams have spent years locking down technical privilege: the admin accounts that hold the keys to the servers. Attackers have quietly moved to what Zscaler calls business privilege: the person who approves invoices, signs supplier contracts, sees the payroll file, or can push a payment through before anyone asks a second question. In a typical Australian small business that person isn't in IT at all. They're the office manager at a Northern Beaches venue, the finance officer at a Central West not-for-profit, or the practice manager at a wealth firm.
Here's the pattern we see in client environments: it's almost always the busy, trusted, long-tenured staffer who gets picked, not the newest hire, because they can make things happen quietly. Attackers map exactly who that is from LinkedIn and a compromised mailbox well before the ransom note ever lands.
What to Actually Do About It
- Work out who holds "business privilege" in your organisation: who can move money or change bank details, and make sure a second person signs off on every request.
- Give those roles your strongest protection: phishing-resistant MFA and tighter mailbox rules, not just the IT admins.
- Verify any unusual payment or contract request out-of-band, by phone, on a number you already have stored, not one supplied in the email itself.
- Run the "what if this account was taken over" drill, not just the "what if we get encrypted" scenario.
Encryption is the part victims notice. The quiet reconnaissance beforehand is the part that decides how bad it gets. We help Australian businesses put the right controls around the people who actually carry the risk, not just the server room. If you're not sure who your business-privilege users are, our cybersecurity team can map it with you.
Sources
- Ransomware Gangs Skip the CEO, Head Straight for the Manager, The Register
- Zscaler ThreatLabz Ransomware Report 2026
Written by Dan Briggs, Head of Relationships, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors from its Brookvale base.
Frequently Asked Questions: Ransomware and Business Privilege
Not Sure Who Your Business-Privilege Users Are?
Our cybersecurity team can map the accounts that carry real financial risk in your business and help you put the right protections in place.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
